Live data from Hacker News

More than 1k people at Twitter had ability to aid hack of accounts

reuters.com

111–120 of 238 posts

Re: More than 1k people at Twitter had ability to aid hack of accounts

#111
post #31

Earlier quoted context omitted.

> The real story here is Twitter's lack of spear-phishing training for their support staff, not support employees have access to support tools. Spear-phishing by its very definition is a highly targeted attack. I wouldn't count on any level of training to prevent someone from getting phished. Given some of the spear phishing campaigns I've seen, I wouldn't trust even myself not to fall for them. It's a problem that n…

FWIW, this is actually quantifiable. We contract with a firm that tests employees' response to spear phishing about once a quarter with varying degrees of "difficulty". Part of an overall scheme that also identifies people who blindly click on things for, uh, further email education.

I'd love to know if you have any data to show if that "further email education" makes any difference in future behaviour...

The cynic in me reckons "Hell no! Those sorts of people are way too often _proud_ of their zero-thought blind clicking and lack of understanding of how things work"...

Re: More than 1k people at Twitter had ability to aid hack of accounts

#112
post #15

Kind of sensationalist. There's thousands of people that have the ability to drain your bank account right now. Your average call center employee wields immense power. The real story here is Twitter's lack of spear-phishing training for their support staff, not support employees have access to support tools .

It's not sensationalist when you realize it directly contradicts Twitter's prior statements from just last year about it: > Twitter, in a statement, said it is aware that "bad actors" will try to undermine its service and that the company "limits access to sensitive account information to a limited group of trained and vetted employees." https://www.npr.org/2019/11/06/777098293/2-former-twitter-em... 1,000 people, in…

It's funny how most people think that 1000 out of 4600 employees having admin access is "not misleading" and counts as a "limited" group. It shows how in the public mind, technology groups should not be held accountable for their actions.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#113

accounts with more than 10,000 followers should at least need two people to change key settings For accounts that could start a war this might be necessary, but for celebrities with >10K followers this sounds expensive and unnecessary to me. To me, it seems like you could instead ensure the admin view of every account has a timestamped log of recent settings changes, including changes done by admins, with a link to t…

‘Two people’ misses the entire problem here. If twitter ‘verified’ means anything, it means a chain of identity has been established between Twitter and the purported owner of that account. That chain should be documented somewhere - there must be some record in the ‘verified account management’ system that says something to the effect of ‘after we gave this actual verified human this token, this email from this addr…

> If twitter ‘verified’ means anything, it means a chain of identity has been established between Twitter and the purported owner of that account.

Not really, a blue checkmark is just a status symbol.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#114

Ha! Did you see in that article that the head of cyber security for AT&T added his two cents in shaming Twitter? AT&T was just in the news recently where employees were accepting bribes that allowed criminals to swap SIMs steal bitcoins from AT&T customers. Unbelievable.

I have a lot of sympathy for the telcos on this. They did not volunteer telephone numbers as universal proof of ID. So their threat model was proportional to their intended purpose of the identifier. If bad guys steal your phone number and run up $100 of calls, the phone company would eat the charges and get the number back. Of course nobody did that because it wasn't worth it. Imagine you own a medium-sized resident…

They not only "did not volunteer" to be a secure identity provider via SMS, they've been actively warning against it for almost a decade:

https://www.itnews.com.au/news/telcos-declare-sms-unsafe-for...

Telcos declare SMS 'unsafe' for bank transactions

By Brett Winterford Nov 9 2012

Communications Alliance chief executive John Stanton, representing the interests of mobile providers Telstra, Optus and Vodafone, took the extraordinary step of of declaring the technology insecure in the wake of numerous reports of Australians being defrauded via a phone porting scam first uncovered in Secure Computing magazine.

"SMS is not designed to be a secure communications channel and should not be used by banks for electronic funds transfer authentication," Stanton told iTnews this week.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#115
I remember during my time with a large mobile carrier in UK I was told of a person in the company who could in theory read any SMS on the network. Mind you this was literally one person for over 30 million customers. He had a high security clearance, extensive security training and the powers vested in him were used mainly to identify scammers and other criminals.

Pretty sure this was a requirement set by law - we need someone to be able to do this, but lets make sure they know what they're doing. It is very weird we dont place the same requirements on social networks.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#116
post #95

Earlier quoted context omitted.

> this sounds expensive and unnecessary to me Should we be OK with what has become a significant communication platform being run with sub-par security because it's "expensive" to do it properly?

Personally I think we need to step back and work out why the fuck anyone is OK with Twitter "accounts that could start a war"? And yet here we are.

There may be a bit of an hyperbole in the expression "accounts that could start a war": there are indeed accounts of people who could start a war, yet I fail to imagine how a single tweet, or a few tweets, by some hacker could actually start a war. Escalate tensions, sure. But I assume world leaders and their advisors don't rely (solely) on tweets before calling the cavalry.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#117

Earlier quoted context omitted.

Bingo. Corrupting two is much less likely.

The key trick isn't so much the two as that they're randomly selected. I moved a large amount of money a few years back to buy my home (I do not like debt, so I saved up until I could afford somewhere to live, then I bought it) The bank's web site lets you type in any amount of money but then it says politely that you can't do this from the web site, please call the bank. I called the bank (they always pick up in 2-3…

> You bribe one employee to pretend someone called and authorised a huge transfer. OK. But then a different random employee has to confirm it. How do you bribe them?

So first bank employee I bribe is one who can update the phone number on your account to one I control (or even better, an employee from your telco who'll let me port your number to my burner phone), the next employee I bribe is the one who pretends the call came in. The different random employee then just does their job confirming the transaction with a call to me. Bingo - I have your house payment...

Re: More than 1k people at Twitter had ability to aid hack of accounts

#118

accounts with more than 10,000 followers should at least need two people to change key settings For accounts that could start a war this might be necessary, but for celebrities with >10K followers this sounds expensive and unnecessary to me. To me, it seems like you could instead ensure the admin view of every account has a timestamped log of recent settings changes, including changes done by admins, with a link to t…

‘Two people’ misses the entire problem here. If twitter ‘verified’ means anything, it means a chain of identity has been established between Twitter and the purported owner of that account. That chain should be documented somewhere - there must be some record in the ‘verified account management’ system that says something to the effect of ‘after we gave this actual verified human this token, this email from this addr…

Twitter's blue check is a growth hack, not a notary public.

Re: More than 1k people at Twitter had ability to aid hack of accounts

#119
post #115

I remember during my time with a large mobile carrier in UK I was told of a person in the company who could in theory read any SMS on the network. Mind you this was literally one person for over 30 million customers. He had a high security clearance, extensive security training and the powers vested in him were used mainly to identify scammers and other criminals. Pretty sure this was a requirement set by law - we ne…

Social networks were never supposed to be important or serious in the same way as phone networks. I would argue they still aren't. At the bottom, they are just time waster websites. You wouldn't demand that level of security of a php forum would you?

Re: More than 1k people at Twitter had ability to aid hack of accounts

#120

Earlier quoted context omitted.

> 1,000 people, including contractors outside the company, is not a "limited group of trained and vetted employees." That's not necessarily true. 20% of the company could fairly reasonably be deemed "limited", and there being a thousand of them doesn't mean they're not trained on their tasks.

Today I learned that Twitter has 4,600 employees. What are they all doing?

Running one of the world's most important communication platforms.
Post reply on HN